
OWN-Defender
Research project reverse-engineering Windows Security Center COM interfaces to trace AV registration through ATL, vtable, WSCAPI, and RPC, with…

Research project reverse-engineering Windows Security Center COM interfaces to trace AV registration through ATL, vtable, WSCAPI, and RPC, with…

Chronicle parser for CORELIGHT and related information.

Real-time network diagnostics in your terminal. One command, zero config, instant visibility.

This publication is a collection of various common attack scenarios on Microsoft Entra ID (formerly known as Azure Active Directory) and how they can…

Prevent SSRF attacks on AWS EC2 via automated upgrades to the more secure Instance Metadata Service v2 (IMDSv2).

Mitigate CVE-2018-6389 WordPress load-scripts / load-styles attacks

POC about how to detect windows kernel debug by pool tag.

Database firewall written in Go

Quick WAF "paranoid" Doctor Evaluation | WAFPARAN01D3 Tool

A framework and taxonomy for identifying, classifying, and reasoning about detection logic bugs in SIEM, EDR, and XDR rules, with concrete examples…

Proof-of-concept tool for detecting AMSI (Antimalware Scan Interface) bypasses and malicious in-memory script activity on Windows endpoints.

Vulnerability Analysis of CVE-2026-83548 affecting SonicWall SMA1000 security systems.

Accompanying PowerShell Modules for DevSec Defense Presentation

Detection of Linux Malware C2 RedXOR - demonstration

This repository documents how deployment of Microsoft Defender for Endpoint on a Windows 11 device, including onboarding via local script, enabling…